VYPR
Unrated severityNVD Advisory· Published Jan 30, 2025· Updated Feb 18, 2025

Reflected Cross-Site Scripting vulnerability in EmbedAI

CVE-2025-0746

Description

A Reflected Cross-Site Scripting vulnerability has been found in EmbedAI 2.1 and below. This vulnerability allows an authenticated attacker to craft a malicious URL leveraging the"/embedai/users/show/" endpoint to inject the malicious JavaScript code. This JavaScript code will be executed when a user opens the malicious URL.

Affected products

2
  • EmbedAI/EmbedAIllm-fuzzy2 versions
    <=2.1+ 1 more
    • (no CPE)range: <=2.1
    • (no CPE)range: 0

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.